https://seclists.org/oss-sec/2026/q3/613: Exiv2 0.28.9 leased
Published Aug 30, 2026
·Updated
Affected Software
1 affected component
exiv2 exiv2=0.28.9
No. The RemoteIo class is used only when Exiv2 is run against a URL rather than a local file, so the described out-of-bounds read and write issues are not triggered by local-file processing.
An attacker would need Exiv2 to be run on a URL serving attacker-controlled content, such as a command that processes an image from a malicious website. The provided example uses an HTTPS URL rather than a local image path.
Exiv2 version 0.28.9 includes fixes for one moderate-severity and six low-severity vulnerabilities. Updating to that release addresses the fixes announced in the provided advisory.